VendorsCiscosecure_firewall_management_centerall versions
Vulnerabilities

Cisco Secure Firewall Management Center

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

187CVEs
CVE-2026-20079
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
Published 2026-03-04 · Analyzed
10.0KEVEPSS 0.758
CVE-2026-20131
Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
Published 2026-03-04 · Analyzed
10.0KEVEPSS 0.334
CVE-2025-20265
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
Published 2025-08-14 · Modified
10.0EPSS 0.158
CVE-2019-16028
Cisco Firepower Management Center Lightweight Directory Access Protocol Authentication Bypass Vulnerability
Published 2020-09-23 · Modified
10.0EPSS 0.034
CVE-2023-20048
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to insufficient authorization of configuration commands that are sent through the web service interface. An attacker could exploit this vulnerability by authenticating to the FMC web services interface and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute certain configuration commands on the targeted FTD device. To successfully exploit this vulnerability, an attacker would need valid credentials on the FMC Software.
Published 2023-11-01 · Modified
9.9EPSS 0.158
CVE-2024-20424
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain HTTP requests. An attacker could exploit this vulnerability by authenticating to the web-based management interface of an affected device and then sending a crafted HTTP request to the device. A successful exploit could allow the attacker to execute arbitrary commands with root permissions on the underlying operating system of the Cisco FMC device or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only).
Published 2024-10-23 · Analyzed
9.9EPSS 0.009
CVE-2020-3318
Cisco Firepower Management Center Static Credential Vulnerabilities
Published 2020-05-06 · Modified
9.8EPSS 0.010
CVE-2016-6433
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.
Published 2016-10-06 · Modified
9.02 PoCEPSS 0.807
CVE-2019-15992
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Code Execution Vulnerability
Published 2020-09-23 · Modified
9.0EPSS 0.041
CVE-2022-20743
Cisco Firepower Management Center File Upload Security Bypass Vulnerability
Published 2022-05-03 · Modified
9.0EPSS 0.040
CVE-2016-1457
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows remote authenticated users to execute arbitrary commands as root via crafted HTTP requests, aka Bug ID CSCur25513.
Published 2016-08-18 · Modified
9.0EPSS 0.037
CVE-2019-12690
Cisco Firepower Management Center Command Injection Vulnerability
Published 2019-10-02 · Modified
9.0EPSS 0.035
CVE-2019-12687
Cisco Firepower Management Center Remote Code Execution Vulnerability
Published 2019-10-02 · Modified
9.0EPSS 0.033
CVE-2019-12688
Cisco Firepower Management Center Remote Code Execution Vulnerability
Published 2019-10-02 · Modified
9.0EPSS 0.033
CVE-2019-12689
Cisco Firepower Management Center Remote Code Execution Vulnerability
Published 2019-10-02 · Modified
9.0EPSS 0.031
CVE-2019-12679
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12686
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12682
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12684
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12685
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12683
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12681
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2019-12680
Cisco Firepower Management Center SQL Injection Vulnerabilities
Published 2019-10-02 · Modified
9.0EPSS 0.030
CVE-2016-1458
The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 allows remote authenticated users to increase user-account privileges via crafted HTTP requests, aka Bug ID CSCur25483.
Published 2016-08-18 · Modified
9.0EPSS 0.024
CVE-2023-20220
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit these vulnerabilities, the attacker must have valid device credentials, but does not need Administrator privileges. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device, including on the underlying operating system, which could also affect the availability of the device.
Published 2023-11-01 · Modified
8.8EPSS 0.011
CVE-2018-0365
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on the targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvb19750.
Published 2018-06-21 · Modified
8.8EPSS 0.009
CVE-2023-20219
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would need valid device credentials but does not require administrator privileges to exploit this vulnerability. These vulnerabilities are due to insufficient validation of user-supplied input for certain configuration options. An attacker could exploit these vulnerabilities by using crafted input within the device configuration GUI. A successful exploit could allow the attacker to execute arbitrary commands on the device including the underlying operating system which could also affect the availability of the device.
Published 2023-11-01 · Modified
8.8EPSS 0.009
CVE-2022-20926
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this vulnerability by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit this vulnerability, an attacker would need valid credentials for a user with Device permissions: by default, only Administrators, Security Approvers and Network Admins user accounts have these permissions.
Published 2022-11-10 · Modified
8.8EPSS 0.009
CVE-2024-20360
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.
Published 2024-05-22 · Analyzed
8.8EPSS 0.008
CVE-2016-6368
A vulnerability in the detection engine parsing of Pragmatic General Multicast (PGM) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. The vulnerability is due to improper input validation of the fields in the PGM protocol packet. An attacker could exploit this vulnerability by sending a crafted PGM packet to the detection engine on the targeted device. An exploit could allow the attacker to cause a DoS condition if the Snort process restarts and traffic inspection is bypassed or traffic is dropped. This vulnerability affects Cisco Firepower System Software that has one or more file action policies configured and is running on any of the following Cisco products: Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services; Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls; Advanced Malware Protection (AMP) for Networks, 7000 Series Appliances; Advanced Malware Protection (AMP) for Networks, 8000 Series Appliances; Firepower 4100 Series Security Appliances; FirePOWER 7000 Series Appliances; FirePOWER 8000 Series Appliances; Firepower 9300 Series Security Appliances; FirePOWER Threat Defense for Integrated Services Routers (ISRs); Industrial Security Appliance 3000; Sourcefire 3D System Appliances; Virtual Next-Generation Intrusion Prevention System (NGIPSv) for VMware. Fixed versions: 5.4.0.10 5.4.1.9 6.0.1.3 6.1.0 6.2.0. Cisco Bug IDs: CSCuz00876.
Published 2017-04-20 · Modified
8.6EPSS 0.030
CVE-2018-0383
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the transfer of files to an affected system via FTP. The vulnerability exists because the affected software incorrectly handles FTP control connections. An attacker could exploit this vulnerability by sending a maliciously crafted FTP connection to transfer a file to an affected device. A successful exploit could allow the attacker to bypass a file policy that is configured to apply the Block upload with reset action to FTP traffic. Cisco Bug IDs: CSCvh70130.
Published 2018-07-16 · Modified
8.6EPSS 0.030
CVE-2018-0233
A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive system memory on an affected device, which could cause a denial of service (DoS) condition. The vulnerability is due to the affected software improperly handling changes to SSL connection states. An attacker could exploit this vulnerability by sending crafted SSL connections through an affected device. A successful exploit could allow the attacker to cause the detection engine to consume excessive system memory on the affected device, which could cause a DoS condition. The device may need to be reloaded manually to recover from this condition. This vulnerability affects Cisco Firepower System Software Releases 6.0.0 and later, running on any of the following Cisco products: Adaptive Security Appliance (ASA) 5500-X Series Firewalls with FirePOWER Services, Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls, Advanced Malware Protection (AMP) for Networks, 7000 Series Appliances, Advanced Malware Protection (AMP) for Networks, 8000 Series Appliances, Firepower 4100 Series Appliances, FirePOWER 7000 Series Appliances, FirePOWER 8000 Series Appliances, Firepower 9300 Series Security Appliances, Firepower Threat Defense for Integrated Services Routers (ISRs), Firepower Threat Defense Virtual for VMware, Industrial Security Appliance 3000, Sourcefire 3D System Appliances. Cisco Bug IDs: CSCve23031.
Published 2018-04-19 · Modified
8.6EPSS 0.024
CVE-2020-3499
Cisco Firepower Management Center Software Denial of Service Vulnerability
Published 2020-10-21 · Modified
8.6EPSS 0.020
CVE-2021-34749
Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability
Published 2021-08-18 · Modified
8.6EPSS 0.017
CVE-2017-12245
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Service vulnerability. If this memory leak persists over time, a denial of service (DoS) condition could develop because traffic can cease to be forwarded through the device. The vulnerability is due to an error in how the Firepower Detection Snort Engine handles SSL traffic decryption and notifications to and from the Adaptive Security Appliance (ASA) handler. An attacker could exploit this vulnerability by sending a steady stream of malicious Secure Sockets Layer (SSL) traffic through the device. An exploit could allow the attacker to cause a DoS condition when the device runs low on system memory. This vulnerability affects Cisco Firepower Threat Defense (FTD) Software Releases 6.0.1 and later, running on any of the following Cisco products: Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls, Firepower 2100 Series Security Appliances, Firepower 4100 Series Security Appliances, Firepower 9300 Series Security Appliances. Cisco Bug IDs: CSCve02069.
Published 2017-10-05 · Modified
8.6EPSS 0.016
CVE-2017-12244
A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause high CPU utilization or to cause a denial of service (DoS) condition because the Snort process restarts unexpectedly. The vulnerability is due to improper input validation of the fields in the IPv6 extension header packet. An attacker could exploit this vulnerability by sending a malicious IPv6 packet to the detection engine on the targeted device. An exploit could allow the attacker to cause a DoS condition if the Snort process restarts and traffic inspection is bypassed or traffic is dropped. This vulnerability is specific to IPv6 traffic only. This vulnerability affects Cisco Firepower System Software Releases 6.0 and later when the software has one or more file action policies configured and is running on any of the following Cisco products: 3000 Series Industrial Security Appliances (ISR), Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services, Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls, Advanced Malware Protection (AMP) for Networks, 7000 Series Appliances, Advanced Malware Protection (AMP) for Networks, 8000 Series Appliances, FirePOWER 7000 Series Appliances, FirePOWER 8000 Series Appliances, Firepower Threat Defense for Integrated Services Routers (ISRs), Firepower 2100 Series Security Appliances, Firepower 4100 Series Security Appliances, Firepower 9300 Series Security Appliances, Virtual Next-Generation Intrusion Prevention System (NGIPSv) for VMware. Cisco Bug IDs: CSCvd34776.
Published 2017-10-05 · Modified
8.6EPSS 0.016
CVE-2021-40116
Multiple Cisco Products Snort Rule Denial of Service Vulnerability
Published 2021-10-27 · Modified
8.6EPSS 0.014
CVE-2020-3302
Cisco Firepower Management Center File Overwrite Vulnerability
Published 2020-05-06 · Modified
8.5EPSS 0.017
CVE-2025-20148
Cisco Secure Firewall Management Center HTML Injection Vulnerability
Published 2025-08-14 · Analyzed
8.5EPSS 0.004
CVE-2023-20063
Cisco Cisco Firepower Threat Defense Software and Cisco Firepower Management Center Code Injection Vulnerability
Published 2023-11-01 · Modified
8.2EPSS 0.004
1 / 5Next →